LuawardDocs

Key system API

Read and change a project's free-key page: its settings, steps, funnel, visits and blocked accounts.

A project's free-key page (luaward.com/k/…) hands out time-limited keys after a visitor does the steps you set. These routes read it and change what is safe to change from a program. Changing needs a key with the keysystem:write scope (Full access has it). To make a temporary key yourself, make an ordinary key with key_days.

Read

GET /v3/projects/:id/key-systems

Returns key_systems. GET …/key-systems/:key_system_id returns one with its steps, in order. A key system has key_system_id, name, slug, page_url, project_id, script_id (the script whose loadstring the page shows), enabled, key_hours, max_keys_per_visitor, allow_extending, allow_forgetting, require_discord, block_vpn, blocked_countries, session_timeout_seconds, enforce_ip_match, steps, created_at and updated_at. A step has step_id, position, title, provider, target_url, required_seconds and active. One that is not in this project answers 404 KEY_SYSTEM_NOT_FOUND.

Change settings

PATCH /v3/projects/:id/key-systems/:key_system_id

FieldRule
name1 to 80 characters.
enabled, allow_extending, allow_forgetting, require_discord, block_vpn, enforce_ip_matchtrue or false.
key_hoursHow long a key lasts: 0.25 to 8760 hours.
max_keys_per_visitor1 to 20.
blocked_countriesUp to 250 two-letter codes in capitals, such as RU.
session_timeout_seconds300 to 86400.
script_idA live script of the same project, or null to show none.

At least one field; the same limits as the dashboard. The answer is the updated key_system. The slug, the page's look and the steps' provider and link are changed in the dashboard.

PATCH /v3/projects/:id/key-systems/:key_system_id/steps/:step_id

active, required_seconds (0 to 600, the shortest time the step may take) and title, at least one. Anything else in the body is ignored.

Funnel, visits and blocks

GET /v3/projects/:id/key-systems/:key_system_id/stats

days is 7 (default) or 30. The answer has the funnel (visit, start, step, complete, claim, block), countries and blocked_because (why visitors were turned away: vpn, country, captcha, bypass, discord, limit).

GET /v3/projects/:id/key-systems/:key_system_id/visits

The latest visits, newest first: limit (1 to 100, default 30) and before (the next_before of the previous page, a timestamp). Each has visit_id, status, step, country, browser, vpn, discord_id, started_at and finished_at. A visitor's address and browser id are never part of it.

GET /v3/projects/:id/key-systems/:key_system_id/blocks

The accounts and addresses the page turns away: block_id, kind (discord, ip or visitor), value and reason. An address or a browser is kept only as a hash, so only its first eight characters are shown. POST …/blocks with discord_id (15 to 22 digits) and an optional reason blocks a Discord account (201 with block_id; 409 ALREADY_BLOCKED if it already is). DELETE …/blocks/:block_id lifts one (404 BLOCK_NOT_FOUND if there is none). Blocking an address is done in the dashboard.